Posts

Showing posts from November, 2021

Who is U2E-Free?

Image
The scam DApp that phished and stole over $50K from me, u2e-free.com  (and its clone u2e-free.net ), runs in crypto wallets has a public promotional website with the address u2e-free.vip . We can learn more about them by visiting that website. u2e-free.vip - promotional website for a scam DApp The website is really simple with only one webpage, a video, and only 2 out links: White paper and Audit . I don't know how original are their video and White Paper, but their  Audit  document is a stolen Audit of the Uniswap project . They stole the document and added the U2E-Free text in, find-and-replace Uniswap with U2E-Free. Stolen document vs. Original document   Code file references in the Audit document: Uniswap i...

DApp Phishing in Coinbase Wallet - I Lost Over $50,000

Image
A few days ago, all my money, $58,797, in my Coinbase Wallet drained from my wallet without me knowing about it until I opened my wallet. I believe there is a major security issue in Coinbase Wallet where users can easily get phished to give a DApp (Decentralized Application) to take control and grant spending permission to an external entity. My empty wallet 😢 Contacting Coinbase/Wallet Support , which is the only way I know of to reach out to them, was not helpful. All they said is that I may have leaked the recovery phrase, without looking into the details I provided . I found a recent review on Google that describes the situation really well. A recent user review on Google Play Store. I am going to describe what happened in details. My brother-in-law showed me his Coinbase Wallet a few weeks ...